Xwiki / Commons
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-31996 | XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution | CRITICAL | 10.0 | Apr 10, 2024 |
| CVE-2023-36471 | HTML sanitizer allows form elements in restricted in org.xwiki.commons:xwiki-commons-xml | CRITICAL | 9.1 | Jun 29, 2023 |
| CVE-2023-29528 | Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml | CRITICAL | 9.1 | Apr 20, 2023 |
| CVE-2023-26055 | XWiki Commons may allow privilege escalation to programming rights via user's first name | CRITICAL | 10.0 | Mar 2, 2023 |
| CVE-2022-24898 | Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml | MEDIUM | 4.9 | Apr 28, 2022 |
Showing 1 to 5 of 5 CVEs